How consent & privacy requests work
Public forms do not require sign-in. Administration and access to records do. A private receipt shows progress only; it is not identity verification and never reveals student records.
| Form / process | Purpose | What completes it |
|---|---|---|
| Parent & school account consent | Start authorization before collecting an under-13 account's details. | Independent verification, delivered notice, reviewed signed parent return or school educational authority, and a one-use email-bound signup authorization. |
| Printable school packet | Direct notice, parent signature, optional school-completed FERPA consent, and school authority record. | Actual school/operator details, secure return, review and evidence reference. Printing or checking a box does not approve an account. |
| Records access | Ask to review your own or your child's authorized records. | Identity/authority verification, scope review and secure delivery to the verified recipient. FERPA requests are coordinated with the school; applicable deadlines run from receipt, not a later verification status. |
| Correction / deletion | Fix inaccurate information or end retention that is no longer authorized or needed. | Actual authorized correction/deletion, provider and school-copy follow-up, and a recorded fulfillment reference. A status change alone does not erase data. |
| Stop collection / withdraw consent | End further student collection or revoke the child's authorization. | Verified target account. The platform stops collection, revokes authorization and sessions, and deactivates youth memberships. Deletion of existing records is a separate request or scheduled process. |
| Cookie / privacy question | Ask about necessary cookies or data practices. | A verified response where personal records are involved. No optional trackers currently exist, so there is no optional cookie consent to collect. |
Creating accounts
Adults and teens aged 13–17 can create an account and confirm their email. School/class codes are optional for signup and required only when using code-based school enrollment. Teacher, parent and administrator access still require actual verified roles; a signup selection does not grant them.
For individual under-13 accounts, the parent or guardian starts the consent case using their email, with no school selection or approval and without entering child details. The parent must complete verified consent; entering an email alone does not activate the account. School-created under-13 accounts are separate organization accounts and may use the school educational authority process. After verification, the adult returns the signed form or the school documents appropriate educational authority. The platform owner reviews evidence and gives the verified adult a private one-use authorization. On /auth/signup choose Under 13, check that authorization first, then enter the approved email and a school alias. A school/class code is separate. No child information should be entered before authorization.
School-created accounts and SSO
In School management → School-managed accounts, an authorized administrator selects an approved school, age range, username, short alias, actual provider email (if using SSO), role and optional student class. The school collection review and under-13 authorization must be completed first. The password is entered once and shared securely; it is not shown in directories. Username-only internal addresses are not mailboxes and use school administrator resets.
Schools request Google, Microsoft, Apple, Clever or ClassLink in Organization single sign-on. The platform owner configures real provider credentials and reviews testing in Platform settings. School-controlled exact domains require separate ownership and student/staff policy review. SSO verifies the actual provider identity before applying the approved school role and optional class. Public email domains, owner/admin auto-grants and unverified claims are rejected. First create or provision the YFLP account through its age/consent process, then use SSO with the same real email. School consent and collection restrictions still apply.
School setup and review
The school first receives organization approval and a separate collection review of its actual agreement, notices, security/vendors and retention/deletion schedule. Illinois school collection is the current enabled scope. Other jurisdictions need a specific review before student enrollment. Schools send the completed packet through their established family channels and retain signed returns securely. School administrators can verify cases within their school; the platform owner authorizes child accounts and records final fulfillment.
Verification and status
Use an independently established school/parent contact channel to verify email control, parental or school authority, and the target account. Do not rely only on the submitted email, a typed signature or the receipt. The public screen shows Submitted, Verified, Approved, Fulfilled, Withdrawn, Denied or Expired. Only authenticated administrators in scope see the queue. Authorization tokens are shown once, stored hashed, tied to the approved email and used once within seven days.
No automated verification, consent or invitation email is sent by these forms. A monitored legal mailbox and staffed school/operator process are needed. Unverified consent contact expires after seven days. Other requests retain their original received date and must be handled within applicable legal deadlines; administrators must track those deadlines even while verifying.
Retention and withdrawal
Student collection reviews and child authorizations expire within one year with deletion scheduled no later than 30 days afterward. Daily jobs remove covered live database records. Consent expiry stops further child collection; verified withdrawal stops it sooner. Provider backups, logs, exported copies and signed evidence require the documented operating process. Review and inspect failed cleanup runs.
Before real child onboarding
The operator must publish its actual legal name, mailing address, phone and monitored email; review provider security and contracts; establish school agreements and direct notices; and implement the signed-return verification process. These forms and controls support that work. They do not certify compliance with every applicable law. Contact legal@yflp.org.
